Sceawere
Vulnerability Detail
CVE-2026-18367UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sophos macOS Local Privilege Escalation
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 1d ago
- Vendor
- Sophos
- Product
- Sophos Endpoint for macOS
- Attack Type
- CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-08-06T22:16:50.010Z",
"pubdate": "2026-08-06T22:16:50.010Z",
"executiveSummary": "A local privilege escalation vulnerability exists in Sophos Endpoint for macOS and Sophos Home for macOS, which allows authenticated local users to execute arbitrary code with root privileges.\nThe affected products include Sophos Endpoint for macOS prior to version 2026.1.1 and Sophos Home for macOS prior to version 10.11.6.\nThis vulnerability introduces severe risk to system integrity and confidentiality, as a malicious actor with standard local access can completely compromise the host operating system.\nExploitation requires local execution capabilities on the target macOS system, meaning an attacker must already have initial user-level access or the ability to execute code locally.\nSuccessful exploitation results in the total takeover of the affected macOS endpoint, enabling attackers to bypass standard security controls, access sensitive data, install persistent malware, or modify system configurations under the security context of the root user.",
"technicalDetails": "The vulnerability stems from insecure handling of local operations within Sophos Endpoint for macOS and Sophos Home for macOS, allowing a local user to manipulate execution flows or leverage insecure inter-process communication mechanisms.\nThe affected components are part of the security software suite designed to run with elevated system privileges to monitor and protect the host operating system.\nBecause the software executes core background services as root, improper validation or unsafe handling of inputs, files, or execution parameters enables privilege escalation vectors.\nThe attack flow requires the adversary to establish an unprivileged execution context locally on the target macOS machine.\nFrom this local context, the attacker interacts with vulnerable application logic, scripts, or binaries managed by the Sophos software.\nBy supplying crafted inputs, leveraging race conditions, or exploiting insecure file permissions, the attacker forces the privileged daemon or helper tool to execute arbitrary code.\nAuthentication requirements are minimal regarding the vulnerability itself, as local users can trigger the flaw without possessing administrative credentials.\nPrivilege requirements are limited to standard local user access, while network exposure is absent due to the local vector requirement.\nPost-exploitation impact includes complete administrative control over the operating system, allowing the adversary to execute arbitrary payloads, tamper with audit logs, disable security agents, and pivot to other resources within the local environment."
}